CVE-2025-2600

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 26, 2025
Updated: Apr 1, 2025
CWE ID 120

Summary

CVE-2025-2600 is a vulnerability affecting the Devolutions Remote Desktop Manager on Windows. It allows an authenticated user to bypass the "Allow password in variable policy" and use elevated passwords despite the restriction. This issue poses a security risk as it enables unauthorized access to sensitive data. Affected versions include those from 2025.1.24 through 2025.1.25 and all versions up to 2024.3.29. Users are advised to update to a patched version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share